| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Sep-03 05:34:56 |
| Detected languages |
English - United States
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses known Mersenne Twister constants
Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
| Suspicious | The file contains overlay data. |
1929 bytes of data starting at offset 0x9a000.
The overlay data has an entropy of 7.90909 and is possibly compressed or encrypted. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | b12eff2fe99407318be8e54c7c3df6b9 🔍 |
|---|---|
| SHA1 | 83c011f64d79374ceb380cf12304c933a14b2be7 🔍 |
| SHA256 | 50b0c0c1ea690326b4b18b2dafc8a60d39425ab32a436d60f5eabd720dd890c0 🔍 |
| SHA3 | c887efc39957f1541afde7f586dfc52566641afaffb159b3ba7e6bba19a6c782 🔍 |
| SSDeep | 6144:htgSmBaoDMuBTBtjulxjJ73v9Bq4DqauKTGqk0MEQjx5xRBhT8PpN/0t6r0VKrNm:hMfzuJfaKThQN4/rpxoSx7WixkWY 🔍 |
| Imports Hash | 97b48a7cd335e0b7242f89e332c2e73e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Sep-03 05:34:56 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x72400 |
| SizeOfInitializedData | 0x28a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000006D350 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xa0000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xa84ed |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 60c1afbca11191773762919602b96ba7 🔍 |
|---|---|
| SHA1 | bbb8925b974221426d897bc96639be70308177e6 🔍 |
| SHA256 | 8a8dc3f02a16bc0a2139ad88eaeb370a549cfa317c013ec8f5e2f0054e316779 🔍 |
| SHA3 | 761638f8fabf1624b43b37ac5ae3dea1c1e017b47f1ef180f1e7d3231ac5fa88 🔍 |
| VirtualSize | 0x72377 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x72400 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.50669 |
| MD5 | 7f4e4109f605b933911ea4bd25b46af2 🔍 |
|---|---|
| SHA1 | 45f29ac5ce0e1329250335d687fa7bd2715cdbc8 🔍 |
| SHA256 | 877accc86aa05771e11e3ef45e69dd728c3078e37b129846ff2582adb7f5918e 🔍 |
| SHA3 | 842dac624907c2b1143b78ae1ad36e37441b411c0fd81a5732f45d93398e0512 🔍 |
| VirtualSize | 0x22802 |
| VirtualAddress | 0x74000 |
| SizeOfRawData | 0x22a00 |
| PointerToRawData | 0x72800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.94783 |
| MD5 | b5af18813324db56a08f61e8945d26fc 🔍 |
|---|---|
| SHA1 | f65431959c48ecaab4c4b06451356473f4c56dbb 🔍 |
| SHA256 | 5b397a94b6cecdc04ec546344df22fb18e04997579c68491e9ff8031841d00e6 🔍 |
| SHA3 | 81f93a2702bbe6077097859eb3f1417fa476fbee491dcc0d7ff0ba25cf8c712f 🔍 |
| VirtualSize | 0x2388 |
| VirtualAddress | 0x97000 |
| SizeOfRawData | 0x1200 |
| PointerToRawData | 0x95200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.47842 |
| MD5 | 7349704bdacce5d06c3190390c291d1e 🔍 |
|---|---|
| SHA1 | f116338b14e554abef3d24c163f295e938385b2e 🔍 |
| SHA256 | 1e60f032ef0ec554259291c4e3f19dc221d1a4fc4e6e53f582bfd8848995533c 🔍 |
| SHA3 | 5e8aab39df88dcb0577199a30865bf16f5bbdb55ab16ec2887c6e8ef86d70f71 🔍 |
| VirtualSize | 0x35e8 |
| VirtualAddress | 0x9a000 |
| SizeOfRawData | 0x3600 |
| PointerToRawData | 0x96400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.82366 |
| MD5 | 11d1748cae04a0874ae786347f497e43 🔍 |
|---|---|
| SHA1 | 28cfa775c119f61476622d4c8242c7c126d3868b 🔍 |
| SHA256 | d36fe06208624b14661ed5285970e27d4e632a9395c2ee3d5a38823b26e8023a 🔍 |
| SHA3 | 6dee411fbc4b0c4ada88eb88dbd4fce5b38f70addeaa50ee6ca9f89fc876844d 🔍 |
| VirtualSize | 0x1e0 |
| VirtualAddress | 0x9e000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x99a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.71377 |
| MD5 | a31fe9fa934c56d09de44a5e77442f74 🔍 |
|---|---|
| SHA1 | dfff0ee07e5f76c2025cb7289923df9d6068d1de 🔍 |
| SHA256 | bce7ecac6740b71cde729387b3305ab36ad1d827be307819fda9868599214e88 🔍 |
| SHA3 | b6daf3632d579bcfcd0fb332f791d90e759c1c3f629b4c88a919bd8653fd4eda 🔍 |
| VirtualSize | 0x26c |
| VirtualAddress | 0x9f000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x99c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 3.74893 |
| WINHTTP.dll |
WinHttpQueryOption
WinHttpQueryDataAvailable WinHttpQueryHeaders WinHttpReceiveResponse WinHttpSendRequest WinHttpSetTimeouts WinHttpSetOption WinHttpReadData WinHttpConnect WinHttpCloseHandle WinHttpCrackUrl WinHttpOpen WinHttpOpenRequest |
|---|---|
| CRYPT32.dll |
CryptProtectData
CryptUnprotectData CertFreeCertificateContext |
| bcrypt.dll |
BCryptCreateHash
BCryptHashData BCryptFinishHash BCryptDestroyHash BCryptGetProperty BCryptSetProperty BCryptGenerateSymmetricKey BCryptDecrypt BCryptDestroyKey BCryptGenRandom BCryptCloseAlgorithmProvider BCryptOpenAlgorithmProvider |
| USER32.dll |
SetCursor
ScreenToClient LoadCursorW FindWindowA MessageBeep MessageBoxW TrackMouseEvent GetMessageW TranslateMessage GetCursorPos SendMessageW DefWindowProcW PostQuitMessage RegisterClassExW CreateWindowExW ShowWindow GetSystemMetrics UpdateWindow BeginPaint EndPaint SetWindowRgn InvalidateRect SetWindowTextA GetWindowTextA GetClientRect DispatchMessageW |
| GDI32.dll |
SetTextColor
SetBkColor DeleteObject DeleteDC CreateSolidBrush CreateRoundRectRgn CreateFontW CreateCompatibleDC CreateCompatibleBitmap BitBlt SelectObject |
| SHELL32.dll |
ShellExecuteW
ShellExecuteExA ShellExecuteA |
| ADVAPI32.dll |
FreeSid
RegDeleteKeyA RegQueryValueExA RegOpenKeyExA RegSetValueExW RegQueryValueExW RegOpenKeyExW RegCreateKeyExW RegCloseKey AllocateAndInitializeSid CheckTokenMembership GetUserNameA |
| ole32.dll |
CoCreateInstance
CoSetProxyBlanket CoInitializeEx CoUninitialize |
| OLEAUT32.dll |
VariantClear
VariantInit |
| gdiplus.dll |
GdipAddPathArc
GdipAddPathBezier GdipAddPathEllipse GdipCloneBrush GdipDeleteBrush GdipCreateSolidFill GdipCreateLineBrush GdipFillRectangle GdipCreateLineBrushI GdipCreatePen1 GdipGetGenericFontFamilySansSerif GdipDeletePen GdipClosePathFigure GdipGetPenWidth GdipCloneImage GdipDeletePath GdipCreateBitmapFromFile GdipCreateFromHDC GdipDeleteGraphics GdipSetSmoothingMode GdipSetTextRenderingHint GdipSetInterpolationMode GdipDrawLine GdipDrawLineI GdipDrawEllipse GdipDrawPath GdipFillRectangleI GdipFillPolygon GdipFillEllipse GdipFillPath GdipDrawImageRect GdipSetClipPath GdipAddPathLine GdipCreatePath GdiplusShutdown GdiplusStartup GdipFree GdipAlloc GdipDeleteFont GdipDrawString GdipCreateStringFormat GdipDeleteStringFormat GdipSetStringFormatAlign GdipDisposeImage GdipSetStringFormatLineAlign GdipSaveGraphics GdipRestoreGraphics GdipCreateFontFamilyFromName GdipDeleteFontFamily GdipCreateFont |
| KERNEL32.dll |
GetFileAttributesExW
GetFileAttributesW FindNextFileW FindFirstFileExW FindFirstFileW FindClose GetLocaleInfoEx FormatMessageA GetCurrentThreadId Sleep SleepConditionVariableSRW GetFinalPathNameByHandleW AcquireSRWLockExclusive ReleaseSRWLockExclusive OpenFileMappingW GetTickCount64 CreateProcessW GetTempPathW QueryDosDeviceW CreateDirectoryW OpenProcess Process32NextW Process32FirstW GetFullPathNameW SetFileInformationByHandle AreFileApisANSI CopyFileW InitializeSListHead MoveFileExW GetFileInformationByHandle CreateToolhelp32Snapshot WaitNamedPipeA GetModuleFileNameW VirtualQuery GetFileInformationByHandleEx WakeAllConditionVariable RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW GetSystemTimeAsFileTime VirtualProtect GetSystemInfo GlobalMemoryStatusEx GetThreadContext GetCurrentThread QueryPerformanceFrequency QueryPerformanceCounter SetLastError GetLastError GetFileSize GetDiskFreeSpaceExA CreateFileW GetSystemFirmwareTable GetVolumeInformationA CreateFileA CreateDirectoryA WideCharToMultiByte MultiByteToWideChar GetProcAddress GetModuleHandleA GetCurrentProcess DeleteFileA GetWindowsDirectoryA GetSystemDirectoryA GetTickCount CreateProcessA GetExitCodeProcess PeekNamedPipe CreatePipe SetHandleInformation GetTempPathA ReadFile GetComputerNameA LocalFree GetModuleHandleW GetModuleFileNameA TerminateProcess ExitProcess GetCurrentProcessId WaitForSingleObject CloseHandle SetFileAttributesA GetFileAttributesA GetEnvironmentVariableA |
| MSVCP140.dll |
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z ?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Id_cnt@id@locale@std@@0HA ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?uncaught_exceptions@std@@YAHXZ ?_Xbad_function_call@std@@YAXXZ ??Bios_base@std@@QEBA_NXZ ?good@ios_base@std@@QEBA_NXZ ?flags@ios_base@std@@QEBAHXZ ?width@ios_base@std@@QEBA_JXZ ?width@ios_base@std@@QEAA_J_J@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ _Xtime_get_ticks ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ ?setf@ios_base@std@@QEAAHHH@Z ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAADD@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ ?_Xbad_alloc@std@@YAXXZ ?_Xinvalid_argument@std@@YAXPEBD@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Xout_of_range@std@@YAXPEBD@Z _Query_perf_counter _Query_perf_frequency _Thrd_detach _Mtx_lock _Mtx_unlock _Cnd_do_broadcast_at_thread_exit ?_Throw_Cpp_error@std@@YAXH@Z ?_Syserror_map@std@@YAPEBDH@Z ?_Winerror_map@std@@YAHH@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ??7ios_base@std@@QEBA_NXZ |
| urlmon.dll |
URLDownloadToFileW
URLDownloadToFileA |
| VCRUNTIME140.dll |
__current_exception
__C_specific_handler strstr memset memmove memcpy memcmp __current_exception_context _CxxThrowException __std_exception_destroy __std_exception_copy __std_terminate |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| api-ms-win-crt-runtime-l1-1-0.dll |
_c_exit
_cexit _get_narrow_winmain_command_line _seh_filter_exe _exit _initterm_e _register_thread_local_exe_atexit_callback _crt_atexit _invoke_watson _configure_narrow_argv _initialize_narrow_environment _errno _initterm exit _beginthreadex abort terminate _register_onexit_function _set_app_type _initialize_onexit_table |
| api-ms-win-crt-string-l1-1-0.dll |
_wcsicmp
tolower wcslen wcsncmp strlen toupper _stricmp isspace |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_callnewh free _set_new_mode |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoul
strtoll strtol |
| api-ms-win-crt-stdio-l1-1-0.dll |
fsetpos
_fseeki64 fwrite setvbuf fread fgetpos fgetc fflush fclose _get_stream_buffer_pointers ungetc __p__commode __stdio_common_vsprintf _set_fmode __stdio_common_vswprintf_s fputc |
| api-ms-win-crt-filesystem-l1-1-0.dll |
_lock_file
_unlock_file |
| api-ms-win-crt-time-l1-1-0.dll |
_time64
_localtime64_s |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
___lc_codepage_func |
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
|
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x17d |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.91161 |
| MD5 | 1e4a89b11eae0fcf8bb5fdd5ec3b6f61 🔍 |
| SHA1 | 4260284ce14278c397aaf6f389c1609b0ab0ce51 🔍 |
| SHA256 | 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df 🔍 |
| SHA3 | 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Oct-10 03:03:35 |
| Version | 0.0 |
| SizeofData | 964 |
| AddressOfRawData | 0x87c50 |
| PointerToRawData | 0x86450 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Oct-10 03:03:35 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0x88014 |
| PointerToRawData | 0x86814 |
| StartAddressOfRawData | 0x140088040 |
|---|---|
| EndAddressOfRawData | 0x14008a110 |
| AddressOfIndex | 0x140098dd8 |
| AddressOfCallbacks | 0x140074e18 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140097600 |
| GuardCFCheckFunctionPointer | 5369187592 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0xcce43b23 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 18 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| C++ objects (35207) | 34 |
| Imports (35207) | 6 |
| C objects (33145) | 1 |
| Imports (33145) | 25 |
| Total imports | 416 |
| C++ objects (35228) | 8 |
| Resource objects (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.